First published: Wed Dec 30 2015(Updated: )
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXHN H108N Firmware | <=zte.bhs.zxhnh108nr1a.h_pe | |
ZTE ZXHN H108N R1A Firmware | ||
ZTE ZXV10 W300 | <=w300v1.0.0f_er1_pe | |
ZTE ZXV10 W300 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8703 is classified as a high severity vulnerability due to the potential for remote authenticated users to bypass access restrictions.
To fix CVE-2015-8703, ensure that the firmware for the ZTE ZXHN H108N R1A or ZXV10 W300 devices is updated to a version that addresses this vulnerability.
CVE-2015-8703 affects ZTE ZXHN H108N R1A devices with firmware versions up to ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices with versions up to W300V1.0.0f_ER1_PE.
CVE-2015-8703 enables remote authenticated users to bypass intended access restrictions and potentially retrieve sensitive credentials and keys.
Yes, CVE-2015-8703 is referenced in multiple security advisories and bulletins, including those available on security-focused websites.